PoC Index

CVE-2010-2568

KEVHIGH 9.3EPSS 91.3%

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
91.32% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-09-15
Published
2010-07-22
Updated
2025-10-22

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related